Check: 2011-B-0146
windows 7 iavm:
2011-B-0146
(in version v1 r32)
Title
Microsoft Office Input Method Editor (IME) Privilege Escalation Vulnerability (Cat II impact)
Discussion
Microsoft has released a security bulletin addressing a vulnerability in Microsoft Office Input Method Editor (IME). Microsoft Office IME resolves the issue associated with entering information in certain languages via a keyboard. To exploit this vulnerability, an attacker would perform specific actions utilizing the MSPY IME toolbar to launch Internet Explorer with system-level privileges. Successful exploitation would allow an attacker to execute arbitrary code with kernel level privileges resulting in the complete compromise of affected systems. At this time, there are no known exploits associated with this vulnerability; USCYBERCOM is not aware of any DoD related incidents. Pinyin IME Elevation Vulnerability - (CVE-2011-2010): An elevation of privilege vulnerability exists due to the way that the Microsoft Office IME (Chinese) improperly exposes configuration options not designed to run on the secure desktop. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Check Content
See IAVM notice and vendor bulletin for additional information. Microsoft Bulletin MS11-088 (2652016). Vulnerable Applications/Systems: Microsoft Pinyin IME 2010 (x86 and x64) Microsoft Office Pinyin SimpleFast Style 2010 (x86 and x64) Microsoft Office Pinyin New Experience Style 2010 (x86 and x64) Verify that the patch has been installed by checking that the following sample file is at the version indicated or later. See the vendor bulletin for additional information and any Vulnerable Systems/Applications not listed below. Imsccore.dll Microsoft Pinyin IME 2010 – 14.0.6009.1000 Imsccfg.dll Microsoft Office Pinyin SimpleFast Style 2010 - 14.0.5810.1000 Microsoft Office Pinyin New Experience Style 2010 - 14.0.5810.1000
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-30822
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |